EU Rules on AI Models Are Enforceable: What Changes

Last updated: August 4, 2026 · By Vishal Swami, Founder & Lead AI Reviewer, AISagely

EU rules on AI models entered full enforcement on August 2, 2026, but the deadline covers a lot less than the headlines suggest. The AI Office and national regulators can now fine companies for banned AI practices and for violating general-purpose AI (GPAI) model obligations — the rules covering models like GPT, Gemini, and Claude. The toughest set of requirements, the ones for high-risk AI systems, got pushed back sixteen months in a deal that only became law a week before the deadline.

Short answer: As of August 2, 2026, EU rules on AI models are enforceable: the AI Office and national regulators can fine GPAI providers and banned-practice violators up to €35 million or 7% of global turnover. But the high-risk AI system rules due the same day were delayed to December 2, 2027 under a Digital Omnibus deal that took effect July 27, 2026. Most member states still lack a working enforcement authority.

ChatGPT homepage — screenshot of chatgpt.com
ChatGPT homepage — screenshot of chatgpt.com

I read the primary legal text and the Commission's own trackers for this one. Secondary coverage of this deadline has been messy. A lot of it was written before the delay was finalized. Here's what's actually live, what got pushed, and what it means if you build on or ship an AI model.

What actually became enforceable on August 2, 2026

Three things turned on this week, not the whole regulation:

  1. Full penalty powers. The AI Office and national market surveillance authorities can now issue fines under Article 99 of the AI Act. Prohibited practices — manipulative AI, social scoring, some biometric categorization — carry fines up to €35 million or 7% of global annual turnover, whichever is higher. Most other violations, including GPAI obligations, cap at €15 million or 3%. Giving regulators false or misleading information tops out at €7.5 million or 1%.
  2. GPAI obligations, now with teeth. Providers of general-purpose AI models have technically been required to publish training-content summaries, maintain technical documentation, and follow a copyright policy since August 2, 2025. What changed this week is that regulators can actually penalize a provider for skipping it.
  3. Article 50 transparency rules, the ones requiring labels on AI-generated content and disclosure of chatbots and deepfakes. I've covered what Article 50 requires in detail and the exact disclosure wording to use elsewhere on this site — that deadline held and wasn't touched by the delay described below.

What didn't change: the ban on prohibited practices itself. That's been law since February 2, 2025. August 2 just armed the regulators with fines for it.

The high-risk AI rules got delayed — here's the new timeline

This is the part most "what changes on August 2" coverage got wrong, because it was written before the ink dried. The full requirements for high-risk AI systems — risk management, human oversight, conformity assessments, the works — were supposed to apply to Annex III systems (hiring tools, credit scoring, education AI, and similar) starting this week too. They don't anymore.

On May 7, 2026, EU negotiators reached a provisional deal to push that deadline out, part of a wider "Digital Omnibus" package. Parliament adopted it on June 16. The Council followed on June 29. It was published in the Official Journal on July 24 and took effect on July 27, 2026 — five days before the original deadline. Under the Gibson Dunn summary of the final text, stand-alone high-risk systems under Annex III now have until December 2, 2027. High-risk systems embedded in regulated products, like medical devices or machinery, move from August 2, 2027 to August 2, 2028. The stated reason: the technical standards needed for conformity checks under Article 40 weren't ready. Regulators didn't want companies certifying against a moving target.

What's live now vs. what got pushed to 2027-2028

Requirement Applies to Status as of August 4, 2026
AI Office/national authority penalty powers All providers and deployers Live since August 2, 2026
Prohibited-practice ban and fines (up to €35M/7%) All providers and deployers Ban live since Feb 2, 2025; fines live since Aug 2, 2026
GPAI obligations (Article 53) for new models Providers of models placed on the market from Aug 2, 2025 Live since August 2, 2025; enforceable since Aug 2, 2026
GPAI obligations for models already on the market Providers of models placed before Aug 2, 2025 Grace period to August 2, 2027 (Article 111)
Article 50 content-labeling/transparency rules Providers and deployers of content-generating AI Live since August 2, 2026
High-risk AI systems, stand-alone (Annex III) HR, credit, education, and similar AI systems Delayed to December 2, 2027
High-risk AI in regulated products (Annex I) Medical devices, machinery, and similar Delayed to August 2, 2028

The enforcement gap: most countries still can't enforce this

Here's the nuance that's easy to miss: the law being enforceable and the law being enforced aren't the same thing. Every EU member state was supposed to designate a market surveillance authority and a notifying authority to actually carry out this enforcement. According to the AI Act’s own national implementation tracker, as of June 17, 2026, only 9 of the 27 member states — Cyprus, Denmark, Finland, Hungary, Ireland, Italy, Lithuania, Malta, and Slovenia — had clearly designated both bodies. Twelve had only partial clarity, and six hadn't designated either one. Finland was first out of the gate, with its Transport and Communications Agency becoming an active enforcer back on January 1, 2026.

Practically, a GPAI provider based in, say, Germany or Poland could break the law today with no fully working national authority yet in place to act on it. That's not a free pass, though. The AI Office still has direct power over GPAI providers and systemic-risk models, no matter what a given country has set up. It's an uneven rollout, not a paper tiger.

Where GPAI providers actually stand right now

The AI Act gives GPAI providers a shortcut: sign the EU's General-Purpose AI Code of Practice, and you get a "compliance presumption" — a lighter path to proving you meet Article 53 and, for systemic-risk models, Article 55. According to the European Commission’s own signatory page, updated July 31, 2026, 21 providers have signed, including Anthropic, Google, Microsoft, OpenAI, Amazon, Cohere, IBM, and Mistral AI. Meta has not signed. xAI signed only the Safety and Security chapter, not the full code.

Not signing doesn't exempt a provider from the law — it just means proving compliance through some other route, with less regulatory goodwill if something goes wrong.

In my testing: checking whether the paperwork is actually public

Article 53(1)(d) requires GPAI providers to publish a training-content summary using a template the AI Office finalized on July 24, 2025. In my testing, I went looking for these summaries the way a curious reader would: searching each provider's help center, not legal filings. OpenAI has a standing help-center article for its EU AI Act obligations (help.openai.com, filed under "EU AI Act"). That's the kind of easy-to-find page I'd expect from a signatory. Not every provider makes this as easy to find. A few bury it behind general "trust center" pages that never mention the AI Act by name. If you're evaluating a model for an EU-facing product, I'd treat "can I find their Article 53 summary in under two minutes" as a rough proxy for how seriously a vendor is taking this.

Common mistakes to avoid

The mistake I'd flag first: assuming August 2, 2026 means the whole AI Act is now in force. It doesn't. The high-risk system rules, arguably the most operationally demanding part of the law, don't bite until December 2027 or August 2028 depending on the category.

Second is assuming a GPAI model is exempt just because it launched before August 2025. It's not exempt, it's on a grace period that runs out August 2, 2027 — and that date is fixed, unlike the high-risk deadlines, which have already moved once.

Third is treating "signed the Code of Practice" as a synonym for "compliant." Signing gets a provider a presumption of compliance for the chapters it covers; it isn't a certificate, and the AI Office can still investigate.

Fourth is assuming your business is safe because your national regulator isn't set up yet. The AI Office enforces GPAI and systemic-risk obligations directly, and a slow national rollout doesn't pause the underlying legal obligation, only the speed of local enforcement.

Tracking what changes next

Because this file keeps moving — the Digital Omnibus is the second real timeline change since the Act entered into force in 2024 — I'd treat any specific date in this space as provisional until you check it against the Commission's own tracker. I log regulatory shifts like this one on AISagely’s AI news hub alongside product launches and rollbacks. If you're choosing which GPAI-backed model to build on, my comparison of the major AI models and Claude vs. ChatGPT breakdown cover how the providers named above actually perform, not just how they comply. For the content-labeling side of the AI Act specifically, see my Article 50 deep dive and disclosure-wording checklist. I track how vendors' compliance claims hold up under testing on my AI tool ratings and AI tool reviews pages.

My take

The honest read: regulators got the stick this week, but the target moved. Arming the AI Office with real fines for GPAI and prohibited practices is a genuine milestone. Those obligations are no longer just aspirational. But pushing the high-risk rules out to December 2027, five days before they were due, tells me the EU itself doubted the system was ready — the standards bodies, the notified bodies, and the companies alike. My caveat for anyone building on AI models right now: don't read "delayed" as "gone." The Digital Omnibus bought time, not an exemption. The next hard deadline, August 2, 2027, for GPAI models that had grace periods, is closer than it looks.

Frequently Asked Questions

Does the EU AI Act apply to US-based AI companies?

Yes, if your AI model or system reaches users or businesses in the EU. Enforcement follows the market the AI reaches, not where the company is headquartered — the same principle that applies to the Act's content-labeling rules.

Were the EU's AI rules delayed or not?

Both, depending on which part. Enforcement powers, GPAI obligations, and the Article 50 transparency rules stayed on schedule for August 2, 2026. The high-risk AI system rules under Annex III were delayed to December 2, 2027, and Annex I rules moved to August 2, 2028.

What happens if my country hasn't set up an enforcement authority yet?

The underlying legal obligations still apply, and the AI Office directly enforces GPAI and systemic-risk obligations regardless of national readiness. A slow national rollout limits local enforcement capacity, not the law itself.

Does the high-risk AI delay mean I can ignore AI Act compliance until 2027?

No. GPAI obligations, the prohibited-practices ban, and Article 50 transparency rules are all enforceable now. Only the Annex III and Annex I high-risk system requirements were pushed out, and companies still need to prepare for those before the new 2027-2028 deadlines arrive.

Is there a cost to comply with the EU AI Act's GPAI transparency rules?

There's no fee to the EU itself. The cost is internal: producing the training-content summary, technical documentation, and copyright policy Article 53 requires, or the engineering and legal time to do it. Signing the free Code of Practice can reduce that burden by giving providers a template path to compliance.